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Remarks : 

Claims 1-25 are pending in the application. All claims stand rejected by the 
Office Action dated June 19, 2006. By this paper, claims 1,15. and 21 are amended 
and claims 27-37 are added. Claim 26 was previously canceled. CD 

m 

It is first noted that Examiner did not specify grounds for rejection of <£> 
dependent claim 1 0. Therefore Applicant respectfully asks Examiner to consider ^ 
claim 10 in light of the current amendments and the remarks below. 



O 



35 U.S.C. § 102(e) m 

Independent claims 1, 15, and 21 are rejected in the Office Action under 35 
U.S.C. § 102(e) as unpatentable over U.S. Publication No. 2003/0212779 to Boyter 
et al. ("Boyter"). 

Claims 1 and 21 are amended to recite "performing remote agentless 
scanning of internal files and data within the internal files on the first network device. . 
. " Similarly, claim 15 is amended to recite that the system comprises "performing 
remote agentless scanning of internal files and data within the internal files on the 
first network device. . . In light of these amendments, Boyter does not teach every 
element of the claimed invention, and thus should not be rejected under 35- U.S.C. § 
102(e). 

The Office Action asserts that Boyter "teaches a system and method for 
network security scanning, . . . scanning network devices connected to a network," 
Further, Boyter is characterized as teaching remote agentless scanning. 
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Applicant respectfully argues that Boyter teaches remote external scanning, 
examining merely ports on network devices, and assessing protocols available on the 
ports. The scanning is confined to examining the ports of devices on the network. In 
contrast, the present invention performs internal scanning, examining files and data 
internal to the network device. 

Boyter teaches "vulnerability scanning" and "checkpng] all designated hosts for 
changes in open ports and vulnerabilities." F*age 1, paragraph [0008]. The abstract 
provides that the claimed invention "scan[s] network nodes to determine open ports 
and vulnerabilities to attack by unauthorized users." Thus, Boyter is concerned with 
"vulnerability to attack by unauthorized users" and seeks to determine infiltration from 
the outside, or external scanning. Boyter teaches scanning for weaknesses that 

. i 

create a risk of infiltration of the device from the outside and does not teach or 
suggest scanning from viruses internal to : the device 

Further, Boyter teaches a method and system "for scanning network nodes for 
detection and reporting of security vulnerabilities, comprising the steps of scanning 
... for determining all active hosts, scanning all ports in each active host for 
determining all open ports, scanning each port of each active host for detecting 
security vulnerabilities, . ; . Page 2, paragraph [0012]; see also page 2, paragraph 
[0013]. The steps and process of scanning and detecting security vulnerabilities 
does not extend beyond examining availability of ports on network devices, and 
assessing protocols available on the ports. The examination of available ports and 
protocols proceeds from an external vantage point using trial-and-error. More 
specifically, Boyter provides, "[t]he step of scanning all ports may comprise the steps 
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of simultaneously scanning each port using a User Datagram Protocol bind attempt 
and a Transmission Control Protocol connection attempt" and subsequently 
evaluating these 'attempts' to determine the status of the port. Page 2, paragraph 
[0012]. 

Still further, Boyter relies, for priority, on Provisional Application No. 
60/376,489, filed on April 30, 2002 (the "Provisional"). The Provisional more clearly 
sets forth the process performed in detecting vulnerabilities providing that the 
purpose of the Port Scanner Daemon (PSD) is "[f]o find all open TCP and UDP ports 
on a host from the full set of 65,535 possible [ports." Provisional, page 21, section 
6.4.1 . The vulnerabilities detected are at the ports. No other vulnerabilities are 
alluded to. Nowhere in the Provisional or Boyter itself is remote scanning of internal 
files and data within the internal files disclosed. 

In direct contrast, the present application teaches and claims a method and 
system for scanning internal'files and data within the internal files on a network 
device. Paragraph 2 of the present disclosure teaches "remote agentless scanning 
includes scanning . . . one or more of a configuration, a file, data, a software version, 
a patch, inventory, hardware, and/or a security vulnerability," Furthermore, to 
perform the scanning of internal files and data, the disclosure contemplates storing 
properties that include "a username and password to logon to the first network 
device," rather than exhaustive trial-and-erroron all ports to find vulnerabilities from 
the outside. Independent claims 1,15, and 21 are amended in this application to 
express this distinguishing limitation. 
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As Boyter does not disclose the, learned limitations, it cannot anticipate 
independent claims 1.15. and 21. Anticipation under section 102 is proper only if the 
reference shows exactly what is claimed. Titanium Me tals Corp. v. Banner, 778 F.2d 

. } 
i 

775 780 227 USPQ 773, 777 (Fed. Cir.:i985); MPEP § 2131.01. Applicants 

' i 

respectfully submit that independent claims represent patentable subject matter. As 
the depending claims include the limitations of the independent claims, they likewise 
represent patentable subject matter. 

i 
i 

35 U.S.C. § 103 

The Office Action rejects dependent claims 5, 13, 19, and 25 under 35 U.S.C. 

' i 

§ 103. Applicant respectfully argues that ip ligjht of the aforementioned amendments 
to independent claims 1 , 15, : and 21, these dependent claims should be approved. 

i 

New claims 27 - 37 provide limitations frhat are specific to scanning internal 
files. For example, the new depending' claims; recite scanning a configuration of 

hardware and software, scanning to determine a software version, scanning a 

i 

software patch, and scanning for viruses. These limitations are not taught by Boyter 
which discloses scanning ports for vulnerabilities from external threats. There is no 
teaching or suggestion in Boyter of internally ^canning hardware and software 
configurations, software versions, software patches, or viruses. 

Should there remain any issues that may be resolved by a telephone 
conference, the examiner is invited to contact the applicant's representative below. 

i 

SakLakc-2B6905-l 0040726-00010 13 

PAGE IS/19 » RCVDAT 9/1912006 11:39:40 AM [Eastern Daylight Time] ■ 8VR:USPTO€FXRF-1/15 * DMS:2738300 • CSD:801 578 6999' DURATION (mm-ss):0448 



09/19/2006 09:44 FAX 801 578 6999 



STOEL RIVES 



@019 



Reconsideration of all pending claims in view, of the amendments and remarks is 



respectfully requested. 



STOEL RIVES LLP 

One Utah Center Suite 1100: 

201 S Main Street 

Salt Lake City, UT 841 1 1-4904 

Telephone: (801)328-3131 

Facsimile: (801)578-6999 . 



Respectfully submitted, 

Altiris, Inc. 

' i i 



By 





teijfstration W. 40,842 
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CO 
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CP 
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